Secure On-Premise Secrets Replication in Cloud

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In cloud computing environments, sensitive information is vulnerable to security threats due to its transfer over networks, and existing methods struggle with secure sharing and replication between servers, especially when new servers need access or when information is updated, leading to potential exposure and security vulnerabilities.

Innovation Solution

A method and system for secure sharing of sensitive information involve determining the trustworthiness of entities, using digital certificates, and encrypting information with public and private key pairs, ensuring that only trusted entities can access and decrypt the sensitive data, thereby preventing unauthorized access and storage in untrusted environments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If sensitive information is transferred over computer networks in cloud computing environments, then data processing and service accessibility are improved, but security vulnerability to eavesdropping and interception increases

Engineering Contradiction:
Improvedata processing capabilityVSAvoidsecurity vulnerability
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent creates encrypted copies of sensitive information that can be securely transmitted across networks. Instead of transmitting plaintext sensitive data, the system generates encrypted replicas that maintain data integrity and confidentiality while enabling cloud-based processing and service accessibility.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent introduces encryption algorithms and security protocols as intermediary layers between the sensitive information and network transmission. These intermediaries transform the data into secure formats, allowing network communication while protecting against eavesdropping and interception threats.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If sensitive information is shared between multiple servers for replication and access, then service continuity and accessibility are improved, but exposure risk and security vulnerabilities increase

Engineering Contradiction:
Improveservice accessibilityVSAvoidexposure risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent applies different security measures to different servers and data copies. Each server receives appropriately encrypted versions of sensitive information with access controls tailored to its specific role and trust level. This localized security approach enables multi-server replication while minimizing overall exposure risk.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent creates multiple encrypted copies of sensitive information that can be distributed across servers. Each copy is secured with encryption keys and access controls, allowing service continuity and accessibility across multiple servers while maintaining security through the use of encrypted replicas rather than plaintext distribution.

Inventive Principle:
Principle #26Copying

3Device complexity

If existing methods are used for sharing sensitive information between servers, then implementation simplicity is maintained, but security strength and protection against unauthorized access are insufficient

Engineering Contradiction:
Improveimplementation simplicityVSAvoidsecurity strength
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent replaces simple, mechanical security methods (such as basic access controls or plaintext sharing) with cryptographic mechanisms. Encryption algorithms, digital signatures, and key management systems substitute for weaker security approaches, providing stronger protection while maintaining reasonable implementation complexity through standardized cryptographic protocols.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS11611541B2Secure method to replicate on-premise secrets in a cloud environment
Publication Date: 2023.03.21 CITRIX SYSTEMS INC
  • US11611541B2 patent drawing
  • US11611541B2 patent drawing
  • US11611541B2 patent drawing

AI summary

Systems and methods for secure sharing of sensitive information in a computing environment. The methods comprise, by a first entity of a first computing environment receiving sensitive information of the first computing environment, receiving a request to share the sensitive information from a second entity of the first computing environment, and determining whether the second entity is a trusted entity included in a list of trusted entities held by a configuration service associated with a second computing environment. If the second entity is not a trusted entity, determining whether the second entity can establish trust by validating a subscription of the second entity with a directory service, and validating a digital certificate corresponding to the second entity with a certificate authority. If the second entity can establish trust or is a trusted entity, sharing the sensitive information with the second entity so as to enable operation of the second entity.